Questions tagged [gdpr]

Questions about the European Union General Data Protection Regulation (GDPR)

https://www.eugdpr.org/

The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) was adopted in 2016 and enters force starting 25 May 2018. It contains provisions for EU citizens and residents to control their personal data, which it explicit defines as:

Any information related to a natural person or ‘Data Subject’, that can be used to directly or indirectly identify the person. It can be anything from a name, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer IP address.

The GDPR applies not only to EU organisations but also to organisations located outside of the EU if they offer goods or services to, or monitor the behaviour of, EU data subjects. It applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location.

Violators can be subject to fines.

1053 questions
63
votes
2 answers

How does SE's arbitration clause hold up under the GDPR?

Today the new Terms of Service of Stack Exchange have been released, sparking a lot of unrest about its arbitration clause; see the comments and answers on the linked meta above, and also this question. Does the GDPR prevent Stack Exchange from…
Adriaan
  • 715
  • 5
  • 10
60
votes
4 answers

Does GDPR include UK customers, or not anymore?

Now that Brexit happened, does GDPR include UK customers, or not anymore?
Nuno
  • 1,043
  • 2
  • 8
  • 14
51
votes
2 answers

Is requesting waiving the right to deletion of contributions against GDPR?

I just got one of those GDPR mails from gitlab.com, which pointed me to a Web page where I had to accept some terms and conditions. The same as everywhere, except this passage: (For GitLab Contributors Only) As part of my voluntary contribution to…
rubenvb
  • 573
  • 4
  • 7
44
votes
2 answers

GDPR + git history

Is name, surname and email in the Git commit history a personal information according to the coming GDPR (General Data Protection Regulation) and is there any special treatment required? Git is a distributed system and therefore it is probably…
Oldrich Svec
  • 541
  • 4
  • 4
35
votes
2 answers

How to store refusal of cookie consent

If a user refuses cookies on a website, then how can that website store that refusal? As far as I can tell, the GDPR requires you to store both consent to and refusal of personal data storage. But it seems to me that there is a catch 22 here: they…
30
votes
2 answers

Accessing public CCTV footage about you

Near me there is a private property which has CCTV aimed away from their property and towards public walkways. I walk past these cameras on a daily basis and they're literally inches away from my face. What are the UK rights for accessing all the…
dollar bill
  • 429
  • 4
  • 6
30
votes
4 answers

ISP is not hashing the password I log in with online. Should I take any action?

I just phoned the customer support number for my ISP for the first time and was surprised to be asked the fourth and fifth characters of my password, specifically the one I used to log into my account on their website, not a special password for use…
fluidj
  • 419
  • 4
  • 6
29
votes
2 answers

How to satisfy GDPR's consent requirement for IP logging?

Countless websites are served by webserver software (Apache, nginx, etc.) which logs the source IP address of every web page visit. The GDPR considers an IP address "personal data" that is subject to the GDPR. The GDPR requires consent of the…
Pistos
  • 393
  • 1
  • 3
  • 6
27
votes
5 answers

Is asking users to waive GDPR compliance a legal way of escaping GDPR data handling requirements?

I have recently come across this part of an app from a well-known US company: Is this a legal way of handling some of the technical obstacles GDPR introduced? Is this a "flexible" interpretation of the law or is it straight up illegal? To give the…
Michal
  • 379
  • 1
  • 3
  • 7
26
votes
2 answers

Can I request a copy of my personal data (GDPR) from email-scammers and sue them if they don't comply?

So, I've been receiving a lot of spammails recently and I'm pretty fed up with them. I've also been wondering, how they got access to my mail-address, so I sent a request of information so I can see, what data they store about me, where they got it…
Florian F.
  • 363
  • 3
  • 6
25
votes
2 answers

Can I request a copy of my password hash with GDPR?

People often use personal information to create them, like first name / date of birth, and people often reuse passwords across several sites, so I guess passwords are considered personal data since they could identify its owner. If a website doesn't…
Benoit Esnard
  • 351
  • 4
  • 8
23
votes
3 answers

In Europe, can I refuse to use Gsuite / Office365 at work?

See above. In a country where GDPR applies (Italy in my case), do I have the right to refuse giving consent to Google and Microsoft to store my personal data, if this account is for work use? Or, in other words, can my employer force me to make a…
Federico Poloni
  • 742
  • 5
  • 15
23
votes
2 answers

Do the GDPR and Cookie-Law regulations apply to localStorage?

We use the localStorage API to store information about the login data to keep the user logged in through various sessions (we do not store personal information), furthermore the localStorage data is not accessible by third-parties. Should we show…
Andrea
  • 333
  • 1
  • 2
  • 4
22
votes
2 answers

Other use of profile photos: legality fair-use and permissions

I'm building an app that works across mobile devices and browsers. There is a chat component and I will be showing the profile photos that I find on the user's phone book (not from the image folders). To make these images visible on the web if the…
Sunil Gupta
  • 357
  • 2
  • 5
22
votes
2 answers

If a request for personal data is made under the GDPR rights but the requestor refuses to give ID for verification what should the company do?

A request for personal data to be deleted is made under the GDPR rights but the requestor refuses to give ID for verification and only provides an email address.
Kin
  • 231
  • 2
  • 3
1
2 3
70 71